My technical analysis shows why AI companies don’t need new laws. An AI agent performing the technical action doesn’t create a new legal category or remove responsibility from the people and companies that authorised, controlled or deployed it. Existing laws already cover unauthorised access, interference and damage, whether carried out by a person, a script or an AI agent. AI doesn’t create a legal vacuum or transfer responsibility to the software. Liability is based on authorisation, control, intent, knowledge, recklessness and harm. The people and companies that built, configured, deployed, commissioned or controlled the system remain subject to existing law. If a train jumps the tracks, you don’t prosecute the train. You establish who designed it, operated it, maintained it or maintained the infrastructure that failed, and who is legally responsible. Autonomous vehicles work differently because either a person or a company can control the vehicle. If a person controls it, that person is responsible. If a company operates a driverless vehicle and it's not controlled by a person, the company operating and deploying the system is responsible. AI agents follow the same pattern. If a person uses an agent to compromise a third party, that person is responsible. If a company deploys the agent or hires a third party to run it on its behalf, the people and organisations that authorised and controlled the activity are responsible. The tool can be a bot, malware framework, macro, or whatever. Liability still depends on who authorised the activity, who controlled the environment, what safeguards were removed, what access was permitted and whose systems were compromised. Recent AI security incidents show why this is already a cybersecurity issue, and why there's no need to create new laws for AI. Calling a security incident a "misconfiguration" explains how they failed to build a proper sandbox. Calling model behaviour "misalignment" describes one interpretation of why the incident happened. Neither term replaces the underlying cybersecurity outcome: unauthorised compromise of third party systems. The companies running the evaluations can authorise offensive activity against systems they controlled. They're not permitted by law to authorise attacks against third parties. "AI did it" doesn’t erase the logs showing who removed safeguards, who configured the environment, who gave the agent its objectives, who commissioned the evaluation and who controlled the infrastructure. New AI specific offences and liability regimes should be stopped until governments identify conduct that existing computer misuse, corporate liability and cybersecurity laws don’t already cover. Companies whose products or contractors repeatedly cause real security incidents shouldn’t help write the regulations that govern them or decide who those regulations apply to. My full technical analysis on Substack breaks down sample laws in the US, UK, EU, Ireland, Canada and Australia, with real enforcement cases to show that existing law already covers unauthorised access and system compromise, including when software or AI performs the technical action. My Substack is always free. paulfwalsh.substack.com/p/existing-law…
